Find out where your business is exposed before something breaks
CloudGrid Africa advises Kenyan businesses on technology risk: what could stop you trading, what a regulator or client will ask you to prove, and what to fix first. Then we do the fixing.
Build secure. Scale smart.
- 18 questions
- 5 minutes
- No sign-up to see your score
Could your business keep serving customers through a full day of internet or power disruption?
- No — operations would stop
- Badly disrupted, no real fallback
- Mostly, with some workarounds
- Yes — a tested fallback exists
Pick an answer to carry on with the scorecard.
What we are usually called in to fix
None of these start as technology problems. They show up as lost days, failed audits and decisions made on bad numbers.
The backup exists. Nobody has ever restored from it.
The first real test happens during an outage, which is the worst time to learn it takes four days.
One person holds every password.
When they are on leave, sick or gone, routine changes stop and nobody can let a supplier in.
A client sends a security questionnaire and nobody can answer it.
The contract waits while someone searches for policies that were never written.
Sales, finance and operations bring three different figures to one meeting.
Each comes from a different spreadsheet, and the meeting is spent reconciling them.
The hosting bill keeps rising and nobody can say which system is responsible.
Resources were added for a project that ended and were never switched off.
Measure first. Decide after.
We do not propose work before we know where you stand, and you should not buy any. These assessments are free, run in your browser, and show the result immediately.
SME Technology Risk Scorecard
One score across six areas: security, continuity, infrastructure, compliance, data and operations. Written for owners and directors, not IT staff. You see the result straight away, without giving an email address.
- Cybersecurity Posture
- Business Continuity & Resilience
- Cloud & Infrastructure Readiness
- Governance & Compliance
- Data Management
- Operational Resilience
Example result. Yours will differ.
Then go deeper where the scorecard points
Cybersecurity Health Check
Use this after a scare, before a client security review, or when cyber insurance or a bank asks what controls you have.
15 questions, about 5 minutesGet my security scoreSME Technology Maturity Assessment
Use this before setting next year's budget, before hiring an IT manager, or when growth has made existing systems feel slow.
18 questions, about 6 minutesAssess my technology maturityBusiness Continuity Checklist
Use this before an audit, when a client asks for your continuity plan, or after an outage that lasted longer than it should have.
15 questions, about 5 minutesCheck my business readinessCloud Readiness Assessment
Use this before signing a migration contract, renewing server hardware, or deciding between public cloud and hosting in Kenya.
15 questions, about 5 minutesEvaluate my cloud readiness
Where we work
Six areas, each described by the business problem it removes.
Cybersecurity and risk advisory
Find the route an attacker would take into your business and close it before someone uses it.
How we approach cybersecurity and risk advisoryCloud and infrastructure
Move off ageing servers without carrying the old problems, or the old costs, into the new environment.
How we approach cloud and infrastructureBusiness continuity and disaster recovery
Decide how long the business can afford to be down, then prove you can recover within that time.
How we approach business continuity and disaster recoveryData protection compliance
Meet the Data Protection Act without stopping the business, and be able to prove it when a customer complains or the regulator asks.
How we approach data protection complianceCustom business systems
Replace the spreadsheets and message groups the business has outgrown with one system built around how you work, secured from the first day.
How we approach custom business systemsTechnology strategy and advisory
Senior technology judgment for businesses that are not ready to hire a full-time CIO.
How we approach technology strategy and advisory
Systems we have built and run
We advise on technology risk from experience of carrying it. These are five of the business systems we have designed, secured and deployed for clients.
Compliance consultancy, Western Australia
Audit and compliance management
A platform a disability-sector compliance firm uses to run client audits: onboarding, policy management, audit preparation, corrective actions and reporting against Australian NDIS standards.
Passenger transport SACCO, Kenya
Operations and owner payouts
Route and trip management, fleet maintenance, fuel tracking and parcels, with revenue distribution to vehicle owners and an audit log behind every payout.
Travel agency, Nairobi
Reservations, ticketing and finance
Bookings, ticketing and invoicing in several currencies with the exchange rate fixed at the time of each transaction, bank and M-Pesa reconciliation, and a client portal.
Supply chain and procurement business, Kenya
Purchasing and shipment tracking
Purchase orders, inventory and payments in one system, with shipments followed by live vessel position and every change recorded in an audit trail.
Church, Kenya
Membership, giving and accounts
A public site, a member portal and online giving, backed by HR, payroll and double-entry accounts with bank reconciliation and budgets for the leadership.
Client names are left off this page. On a review call we can walk you through any of these. How we build systems like these
Advice from people who also run the systems
Plenty of firms will sell you a product, and plenty will write you a report. These are the reasons to talk to us instead.
- We operate what we recommendOur managed cloud, backup and recovery platforms run from Raxio Data Centre in Nairobi, a Tier III facility. Your data can stay in Kenya.
- We build systems and we break into themThe same practice designs production infrastructure and runs offensive security assessments, so designs are tested against how attacks happen.
- We work to the rules you are measured byData Protection Act 2019, CBK guidance, ISO 27001 and PCI-DSS. Findings are mapped to the clause an auditor will cite.
- We measure before we proposeEvery engagement starts from an assessment, so you can see why each recommendation is on the list and what to leave for later.
- You deal with the founderThe person who scopes the work is the person accountable for it. There is no account manager in between.
I started CloudGrid Africa because too many businesses here were sold technology they didn't need, by people who never understood the problem. I wanted to build something different: work that's honest, accountable, and built for how East African businesses run.
Denis Murila, founder
Denis founded CloudGrid Africa and leads its engagements.
His background covers infrastructure engineering, cloud architecture, cybersecurity, business continuity and data. He builds production systems and also tests them the way an attacker would, which shapes how he advises: start from how things fail, put a cost on it, and fix the expensive failures first.
He works with owners, managing directors and finance and operations leads who need a straight answer about technology risk without the jargon.
The Resilient Business Brief
One email a month for owners and directors. No product promotion.
Each issue carries the latest Compliance Decoder, our series on Kenyan data protection law.
- One incident or outage worth learning from, and what it would have cost you
- The latest Compliance Decoder: one data protection rule, explained from a real ODPC or court decision
- One action you can hand to your team that week
Unsubscribe from any issue. Your address is used for the Brief and nothing else. Privacy policy
Not sure where to start? Start with the scorecard.
Eighteen questions, about five minutes. You see your score and your three weakest areas without giving an email address.